CVE-2025-49630

Source
https://cve.org/CVERecord?id=CVE-2025-49630
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49630.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-49630
Aliases
Downstream
ALPINE (1)
AZL (4)
BELL (1)
CLSA (5)
DEBIAN (1)
MGASA (1)
MINI (1)
OESA (1)
openSUSE (2)
RHSA (11)
RLSA (3)
ROOT (1)
SUSE (7)
UBUNTU (1)
Related
Published
2025-07-10T16:57:40Z
Modified
2026-09-23T03:45:12Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache HTTP Server: mod_proxy_http2 denial of service
Details

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2.

Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".

Database specific
{
    "cna_assigner":  "apache",
    "cwe_ids":  [
        "CWE-617"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49630.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "2.4.26"
                },
                {
                    "last_affected":  "2.4.63"
                }
            ],
            "source":  "AFFECTED_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "introduced":  "2.4.26"
                }
            ],
            "source":  "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/apache/httpd

Affected ranges

Type
GIT
Repo
https://github.com/apache/httpd
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "2.4.26"
        },
        {
            "fixed":  "2.4.64"
        }
    ],
    "source":  "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49630.json"